Talha Tariq

124 posts

Talha Tariq

Talha Tariq

@0xtbt

CTO Security @ Vercel. Previously at HashiCorp. Microsoft, PwC. Security researcher & photographer. Views are my own

Hibernating Katılım Temmuz 2012
1.1K Takip Edilen485 Takipçiler
Menjòmetre
Menjòmetre@Menjometre·
🚨 ÚLTIMA HORA 🚨 Vercel ens ha tancat el compte on teníem allotjada la web. Algú ha "reportat" la nostra plataforma a Vercel. Segons ells, l'ús que fa Menjometre va en contra de les Directrius d'Ús Just i/o els Termes del Servei. Migrarem a un nou proveïdor de serveis.
Menjòmetre tweet media
Català
98
949
1.7K
134K
Talha Tariq retweetledi
Guillermo Rauch
Guillermo Rauch@rauchg·
Today we partnered with Meta to disclose a critical vulnerability in React Server Components, impacting Next.js. Huge credit to Lachlan Davidson for responsibly reporting this to Meta and to our industry partners for responding quickly to our call-to-action. This is how open source security is supposed to be: responsible disclosure, fast mobilization, and close collaboration. Within 72 hours, we patched React, shipped WAF mitigations for all Vercel customers, and coordinated major cloud and security providers to protect their customers in the same way. The united response across the ecosystem has been incredible. AWS, Microsoft, Cloudflare, Fastly, Akamai, F5, Google, Deno, Netlify, Railway, Fly, and others moved quickly with platform protections and clear guidance to their customers. As a reminder, if you’re running Next.js 15 or 16, please upgrade immediately to 15.5.7 or 16.0.7. Vercel customers have platform-level protections, but upgrading is still a must. Ref: vercel.com/changelog/cve-…
English
30
53
695
92.3K
Talha Tariq retweetledi
Guillermo Rauch
Guillermo Rauch@rauchg·
We’ve got confirmation of a working #react2shell POC being shared. We’ve verified Vercel’s Web Application Firewall is successfully blocking this known variant. We are also seeing bad actors attempt exploitation. Upgrading React & frameworks remains a top priority.
English
9
19
267
50.5K
John Treadway
John Treadway@JohnTreadway·
@0xtbt @armon @QuinnyPig @HashiCorp I saw the privacy policy. I just don’t know how you manage account closing and deleting all user data without automation given your size and scale.
English
1
0
0
0
Corey Quinn
Corey Quinn@QuinnyPig·
"You must contact us to close your account" is a dark pattern; sad to see @HashiCorp using it.
English
16
18
435
0
John Treadway
John Treadway@JohnTreadway·
@armon @QuinnyPig @HashiCorp @QuinnyPig said “close,” not downgrade. Close - as in delete account, scripts and all data. Would like to hear from @0xtbt if $hcp complies with GDPR and other regs re not retaining user data after account is closed given the lack of automation for this process.
English
1
0
1
0
Talha Tariq retweetledi
David McJannet
David McJannet@davidmcj·
We just released our second annual HashiCorp State of Cloud Strategy Survey, with some interesting insight into what enterprises are doing in the cloud. 1/10
English
1
7
28
0
Talha Tariq
Talha Tariq@0xtbt·
@Joseph_Marks_ Basic cybersecurity hygiene matters, ransomware and extortion targets are more than just about money, public and private sector threat information sharing needs to be stronger and supply chain security needs to be top of mind for critical infrastructure
English
0
0
0
0
Joseph Marks
Joseph Marks@Joseph_Marks_·
The Colonial pipeline ransomware attack’s first anniversary is Saturday. How has the world changed? What are the lessons? Share thoughts here for the Cybersecurity 202.
English
41
44
133
0
Talha Tariq retweetledi
Torq
Torq@torq_io·
We're thrilled to welcome Talha Tariq (@0xtbt) to our CISO Advisory Board. Talha is the Chief Security Officer at @HashiCorp. He brings 20 years of experience building & scaling security programs from startups to Fortune 100 organizations. Give Talha a warm welcome!
Torq tweet media
English
0
7
18
0
Talha Tariq
Talha Tariq@0xtbt·
Oregon is beautiful!
Talha Tariq tweet media
English
1
0
6
0
Talha Tariq
Talha Tariq@0xtbt·
@nomadlogicLA @ryanaraine as mentioned in our disclosure there is no evidence of any malicious change or abuse, our key rotation is a proactive measure
English
1
0
7
0
Talha Tariq
Talha Tariq@0xtbt·
@christophetd @armon @HashiCorp @mitchellh The existing .sig files are currently being left as-is to preserve working behavior on existing Terraform releases. We're in the process of producing patch releases for Terraform which will verify against the new key.
English
0
0
1
0
Renee Shah
Renee Shah@reneeshah123·
Who are the best female angel investors for infrastructure? If they've built complex distributed systems, even better. Thank you 🥂
English
12
13
106
0
Talha Tariq
Talha Tariq@0xtbt·
@tomloverro Oh I had no idea - stay blessed and stay healthy ! This world needs people like you
English
0
0
1
0
Tom Loverro
Tom Loverro@tomloverro·
11 years ago I was diagnosed with a serious form of cancer and was unsure if I’d have a career or family or, frankly, live. I feel blessed to be alive today and have found personal happiness and a fostering professional environment.
English
12
7
583
0
Jeff Mitchell
Jeff Mitchell@jefferai·
Can't wait to talk about Redacted with @ppacent! Join us if you want to hear all about Redacted!
Jeff Mitchell tweet media
English
5
7
16
0